Google Photos – unlimited photo and video storage 3.0.0 (iOS / App Store)

175x175bb (62)

This application is available for iOS. This app is designed to be a photo manager and auto-organized and searchable gallery. The latest build was released on Jul 05, 2017. Our latest check was performed on Mar 26th, 2017.

Findings Summary

Our examination revealed total 45 items, where were 17 DAR items and 28 DIT items found. Among DAR items were found 0 worst items, 0 bad items, 17 good items, and 0 best items. Among DIT items were found 0 worst items, 28 bad items, 0 good items, and 0 best items.

Below you find 2 infographics summarizing what we described above. Each image provides information about both DAR and DIT items.

 

 

This slideshow requires JavaScript.


Everything presented below is related to well-known CWEs, such as Sensitive data leakage [CWE-200], Unsafe sensitive data storage [CWE-312], Unsafe sensitive data transmission [CWE-319]. You can read more about it here.

Now let’s go deeper and examine each data item’s protection level.

 

Application Description

Let’s cite the description of this application below:

Google Photos is a smarter home for all your photos and videos, made for the way you take photos today.
“The best photo product on Earth” – The Verge
“Google Photos is your new essential picture app” – Wired
“Upload the pictures, and let Google Photos do the rest” – The New York Times

  • FREE UNLIMITED STORAGE: Back up unlimited photos and videos for free, up to 16 megapixels and 1080p HD. Access from any device and photos.google.com—your photos are safe, secure, and private to you.
  • FREE UP SPACE: Never worry about running out of space on your phone again. Photos that are safely backed up can be removed from your device’s storage in just a tap.
  • VISUAL SEARCH: Your photos are now searchable by the people, places and things in them—no tagging required.
  • SMARTER SHARING: With smart sharing suggestions, giving your friends the photos you took of them is painless. And they can add their photos, too, so you’ll finally get the photos you’re actually in.
  • SEND PHOTOS IN SECONDS: Don’t waste your data by texting and emailing photos. Instantly share up to 1,500 photos with anyone, right from the app.
  • MOVIES AND GIFS, MADE FOR YOU: Get automatically created movies, collages, GIFs, panoramas, and more from your photos. Or easily create them yourself.
  • MOTION STILLS: Advanced stabilization turns your Live Photos into beautiful looping videos or GIFs.
  • ADVANCED EDITING: Transform photos with a tap. Use intuitive and powerful photo and video editing tools to apply content-aware filters, adjust lighting, and more.
  • SMART AUTOMATIC ALBUMS: Tell better stories, without the work. Automatically get a new album with just your best shots after an event or trip, then invite others to add their photos.
  • REDISCOVER: It’s easier than ever to relive your memories. Get collages of photos you took a year ago on this day – perfect for #tbt.
  • ON YOUR TV: View your photos and videos on your TV with Chromecast and Airplay support.

Note: Face grouping is not available in all countries.
For the latest updates from the team, follow us on Twitter at @googlephotos
Using GPS in the background can decrease battery life. Google Photos doesn’t run GPS in the background unless you turn on optional features.

 

Protection levels.

Locally stored data (Data-at-Rest, DAR).

Locally stored data groups include Credentials Information, Account Information, Media Information, Device Information, Application Information.
The average DAR value is 6.50 points (7.00 points of system protection and 6.00 points of own protection). It is higher than a typical value (3.5 points, where’s 7 points of system protection and 0 points of own protection).

Items with average value 6.50 points (7 points of system protection, 6 points of own protection) means data protection levels have following definitions. Frankly talking, protection and privacy issues are still possible but might involve interaction with an app code where system protection level means – root/jailbreak is required but not possible without wiping device data, and own protection level means – data is not available in backups.

– Credentials (IDs) (‘Credentials Information’ Group) – Only account IDs like app or 3rd party user IDs including emails, phone number, usernames, etc. (depends on apps). This data item related to mentioned group meant to be any types of credentials including basic (IDs only), passwords, tokens, etc.,

– Credentials (Tokens) (‘Credentials Information’ Group) – Different tokens used to get access to your account, except for passwords but including app or 3rd party tokens, secret keys, etc. (usually give full access to your account). This data item related to mentioned group meant to be any types of credentials including basic (IDs only), passwords, tokens, etc.,

– Account Data (‘Account Information’ Group) – Basic info about account like name, a list of sub-account (e.g. financial or other) and some linked data like a phone number. This data item related to mentioned group meant to be any info related to profiles, basic credential IDs like email or username or phone number plus some more info depends on applications,

– Media Data (‘Account Information’ Group) – Any info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any info related to profiles, basic credential IDs like email or username or phone number plus some more info depends on applications,

– Media Data (‘Media Information’ Group) – Any info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– URLs (‘Media Information’ Group) – Different types of URLs referred to your files stored in clouds, profiles, social accounts, media files available online, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– GEO Data (‘Media Information’ Group) – Any GEO info stored as plain text referred to the places or tracked activity. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Account Data (‘Media Information’ Group) – Basic info about account like name, a list of sub-account (e.g. financial or other) and some linked data like a phone number. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Preview (‘Media Information’ Group) – Some pieces of info downloaded locally or to show only on display only like a preview of emails, social posts, documents, thumbnails, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Tracked Data ‘n’ Favorites (‘Media Information’ Group) – Any favorites data or tracked data marked as desirable by users and for users (Means, user is on FB messenger, Viber, bank client or favourite hotel, room type, flight route, airline). This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Place Details (‘Media Information’ Group) – Any info about public place (city, country, address, contacts) stored in text or media file format. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Personalization (‘Media Information’ Group) – Info describes user preferences, favorites, tracked data, search requests, suggestions, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Meta (‘Media Information’ Group) – Any info that gives extra data like EXIF. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Device Data (‘Device Information’ Group) – Device ID, Device Name, Device OS Name and Version, and jailbroken/root status. This data item related to mentioned group meant to be details about your device,

– Application Configs (‘Application Information’ Group) – Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any info related to the app, app settings, including installed apps or installers,

– Account Settings ‘n’ Configs (‘Account Information’ Group) – Information about your account settings and configurations. This data item related to mentioned group meant to be any info related to profiles, basic credential IDs like email or username or phone number plus some more info depends on applications,

– Screen Snapshots (‘Media Information’ Group) – Screenshots of your device screen running certain apps; common as an iOS app multitasking feature (app swipes) or browser tab swipes. This data item related to mentioned group meant to be any data like photo, image, video, audio

Also, keep in mind, using jailbroken device means the system protection level is 0 points and you’re using out-of-date iOS < 8.3 the system protection level is 2 points. If some data marked as shareable via iTunes, then the system protection level is 4 points.

Transferred data (Data-in-Transit, DIT).

Transferred data groups include Credentials Information, Account Information, Media Information, Location ‘n’ Maps Information, Device Information, Application Information.
The average DIT value is 4.50 points (5.00 points of system protection and 4.00 points of own protection). It is higher than a typical value (4 points, where’s 4 points of system protection and 4 points of own protection).

Items with average value 4.50 points (5 points of system protection, 4 points of own protection) means data protection levels have following definitions. Frankly talking, data available if it’s allowed only and may require user action where system protection level means – some techniques are available to developers to keep connection bypassing system settings, like proxy settings, etc., and own protection level means – bypassed by fake/stolen root certificates.

– Credentials (IDs) (‘Credentials Information’ Group) – Only account IDs like app or 3rd party user IDs including emails, phone number, usernames, etc. (depends on apps). This data item related to mentioned group meant to be any types of credentials including basic (IDs only), passwords, tokens, etc.,

– Credentials (Passwords) (‘Credentials Information’ Group) – Well-known passwords or PINs you’re using to get access to your account (usually it is worse than tokens because it gives full access to your account). This data item related to mentioned group meant to be any types of credentials including basic (IDs only), passwords, tokens, etc.,

– Credentials (Tokens) (‘Credentials Information’ Group) – Different tokens used to get access to your account, except for passwords but including app or 3rd party tokens, secret keys, etc. (usually give full access to your account). This data item related to mentioned group meant to be any types of credentials including basic (IDs only), passwords, tokens, etc.,

– Account Data (‘Account Information’ Group) – Basic info about account like name, a list of sub-account (e.g. financial or other) and some linked data like a phone number. This data item related to mentioned group meant to be any info related to profiles, basic credential IDs like email or username or phone number plus some more info depends on applications,

– Media Data (‘Account Information’ Group) – Any info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any info related to profiles, basic credential IDs like email or username or phone number plus some more info depends on applications,

– Media Data (‘Media Information’ Group) – Any info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– URLs (‘Media Information’ Group) – Different types of URLs referred to your files stored in clouds, profiles, social accounts, media files available online, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– GEO Data (‘Media Information’ Group) – Any GEO info stored as plain text referred to the places or tracked activity. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Account Data (‘Media Information’ Group) – Basic info about account like name, a list of sub-account (e.g. financial or other) and some linked data like a phone number. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Contact Profile (‘Media Information’ Group) – Full info about contacts including name email id, phone numbers, gender, linked accounts, geodata, stream and social activity. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Preview (‘Media Information’ Group) – Some pieces of info downloaded locally or to show only on display only like a preview of emails, social posts, documents, thumbnails, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Media Stream (‘Media Information’ Group) – Any info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Tracked Data ‘n’ Favorites (‘Media Information’ Group) – Any favorites data or tracked data marked as desirable by users and for users (Means, user is on FB messenger, Viber, bank client or favourite hotel, room type, flight route, airline). This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Place Details (‘Media Information’ Group) – Any info about public place (city, country, address, contacts) stored in text or media file format. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Personalization (‘Media Information’ Group) – Info describes user preferences, favorites, tracked data, search requests, suggestions, etc. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Meta (‘Media Information’ Group) – Any info that gives extra data like EXIF. This data item related to mentioned group meant to be any data like photo, image, video, audio,

– Personalization (‘Location ‘n’ Maps Information’ Group) – Info describes user preferences, favorites, tracked data, search requests, suggestions, etc. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– GEO Data (‘Location ‘n’ Maps Information’ Group) – Any GEO info stored as plain text referred to the places or tracked activity. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Media Data (‘Location ‘n’ Maps Information’ Group) – Any info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Address Data (‘Location ‘n’ Maps Information’ Group) – Home, work or another type of owner address stored by apps. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Location History (‘Location ‘n’ Maps Information’ Group) – The history list of addresses, geodata, etc. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Tracked Data ‘n’ Favorites (‘Location ‘n’ Maps Information’ Group) – Any favorites data or tracked data marked as desirable by users and for users (Means, user is on FB messenger, Viber, bank client or favourite hotel, room type, flight route, airline). This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– GEO Snapshots (‘Location ‘n’ Maps Information’ Group) – Image-based snapshots of geodata info referred to the places. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Place Details (‘Location ‘n’ Maps Information’ Group) – Any info about public place (city, country, address, contacts) stored in text or media file format. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Maps Data (‘Location ‘n’ Maps Information’ Group) – Map data loaded by internal (native) or third party map applications like Apple/Google Maps or another one. This data item related to mentioned group meant to be any geodata from trackers, social networks, GPS, etc.,

– Device Data (‘Device Information’ Group) – Device ID, Device Name, Device OS Name and Version, and jailbroken/root status. This data item related to mentioned group meant to be details about your device,

– Application Configs (‘Application Information’ Group) – Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any info related to the app, app settings, including installed apps or installers,

– Account Settings ‘n’ Configs (‘Account Information’ Group) – Information about your account settings and configurations. This data item related to mentioned group meant to be any info related to profiles, basic credential IDs like email or username or phone number plus some more info depends on applications

Keep in mind if you’re using out-of-date iOS < 9.0, the system level equals 2 points instead of 4. It means your data can be stolen without involving your actions.

Privacy Policy

Full application privacy policy is available here.

You may find privacy policy details proceeding the link above to compare developer’s vision on data protection with our results.